
How AI Is Reshaping Automotive Cybersecurity
The automotive industry stands on the brink of transformation, driven significantly by artificial intelligence (AI). As we embrace AI’s promise of convenience and efficiency across automotive functionalities, we must also consider the new cybersecurity challenges and potential threats it introduces.
Understanding AI’s Impact on Automotive
From generative AI enhancing software development to sophisticated in-vehicle voice assistants, AI has swiftly permeated automotive functionalities.
Recent industry announcements, including those by Mercedes and BYD regarding advanced AI integration, illustrate a broader shift toward increasingly sophisticated AI capabilities.
Yet, beneath the promising surface lies a complex cybersecurity landscape we cannot afford to overlook.
The Two Sides of AI
Enhancing Cybersecurity
AI can greatly enhance cybersecurity in several ways:
- Accelerated Threat Detection: AI could improve threat assessment accuracy, anomaly detection, and incident investigation, offering detailed and rapid insights.
- Optimized Data Management: Vehicles generate vast amounts of security-related events. AI can help filter out irrelevant information, prioritize critical alerts, and provide meaningful context, enhancing threat identification and response efficiency.
- Automating Cybersecurity Tasks: AI may automate routine cybersecurity tasks, potentially reducing the operational burden and allowing human experts to focus on more complex challenges, where human expertise is truly required.
Emerging Risks
However, AI also introduces new risks, creating new potential attack vectors. Attackers could leverage AI to craft convincing phishing emails, quickly exploit vulnerabilities, and automate malicious activities, significantly escalating the threat landscape and accelerating the attacker’s capabilities.
Additionally, the integration of AI itself into vehicle functions creates completely new attack surfaces. AI assistants for example could be manipulated via well known techniques such as code injection to execute unauthorized tasks, potentially compromising vehicle security. In case an attacker succeeds in influencing the input of such an AI assistant, he might be able to use it to gain access or control different vehicle functions. This could theoretically allow the attacker to compromise private information, modify expected behavior (such as navigation instructions, misleading drivers) or possibly even directly influence safety features such as headlights, door locks or brakes. These scenarios underline the critical importance of robust security measures to counteract such advanced threats.
A vivid illustration of these risks comes from a recent penetration test conducted by PlaxidityX’s automotive penetration testing research team. Exploiting vulnerabilities through the vehicle’s voice assistant interface, our team successfully demonstrated potential control over core vehicle functions, highlighting the criticality of rigorous cybersecurity frameworks.
Safeguarding Vehicles in the AI Era
The convergence of AI and automotive technology demands proactive and rigorous cybersecurity strategies, such as:
- Adopting Standards and Regulations: Aligning with frameworks like the EU’s AI Act and ISO 8800 ensures a structured and regulated approach to AI deployment.
- Restricting AI Permissions: Limiting AI capabilities to essential functions reduces exploitation risks.
- Continuous Cybersecurity Monitoring: Implementing robust vulnerability assessments, penetration testing, and intrusion detection systems is essential.
- Remote AI Model Updates: Ensuring the ability to update or disable AI models remotely is crucial for immediate response to emerging threats.
Realizing AI’s Full Potential Safely
AI undoubtedly transforms automotive cybersecurity, promising significant advancements. Yet, embracing this potential responsibly involves rigorous safeguarding measures. AI’s integration in vehicles requires ongoing vigilance and adaptability from both cybersecurity professionals and automotive stakeholders alike.
At PlaxidityX, our mission remains clear: harness AI’s power responsibly to foster innovation without compromising security. We are adding AI based analytics and chatbot to our XDR solution so VSOC staff can focus on valuable insights. We develop AI capabilities to be embedded within our in-vehicle intrusion detection sensors and the IdsR to connect the dots of seemingly independent events to uncover cyber incidents, and we are leveraging AI to eliminate false positives.
Let’s navigate this transformative journey together, fully aware of both the risks and the immense opportunities AI presents.
Published: July 16th, 2025